Get KYC validation media
curl --request GET \
--url http://api.gu1.ai/api/kyc/validations/{id}/media \
--header 'Authorization: Bearer <token>'import requests
url = "http://api.gu1.ai/api/kyc/validations/{id}/media"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('http://api.gu1.ai/api/kyc/validations/{id}/media', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "http://api.gu1.ai/api/kyc/validations/{id}/media",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "http://api.gu1.ai/api/kyc/validations/{id}/media"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("http://api.gu1.ai/api/kyc/validations/{id}/media")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("http://api.gu1.ai/api/kyc/validations/{id}/media")
http = Net::HTTP.new(url.host, url.port)
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_bodySession-based validation
Get KYC validation media
Download document images, portrait, liveness video, and other assets stored for a session-based KYC validation β in the gu1 KYC API for identity verification.
GET
/
api
/
kyc
/
validations
/
{id}
/
media
Get KYC validation media
curl --request GET \
--url http://api.gu1.ai/api/kyc/validations/{id}/media \
--header 'Authorization: Bearer <token>'import requests
url = "http://api.gu1.ai/api/kyc/validations/{id}/media"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('http://api.gu1.ai/api/kyc/validations/{id}/media', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "http://api.gu1.ai/api/kyc/validations/{id}/media",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "http://api.gu1.ai/api/kyc/validations/{id}/media"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("http://api.gu1.ai/api/kyc/validations/{id}/media")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("http://api.gu1.ai/api/kyc/validations/{id}/media")
http = Net::HTTP.new(url.host, url.port)
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_bodyOverview
After a session-based KYC validation finishes (for example approved), media references appear insidedecision on GET /api/kyc/validations/:id (document images, portrait, liveness video, nested images, etc.).
Current format: each reference is usually a kyc/... key (a path string). Download bytes with the media endpoint below and your API key.
Decision shape: feature results appear as both singular objects and one-element arrays (for example id_verification and id_verifications[0]). Image fields may exist on either shape; Gu1 keeps them in sync. See KYC webhook events for a full decision example.
Older rows: some validations still have HTTPS URLs in decision (short-lived links from the verification flow). Use those URLs directly (for example in an <img> or a server-side fetch) while they remain valid. They are not passed to GET .../media?key= β that parameter is only for kyc/... keys.
This page applies to full session KYC (global_gueno_validation_kyc). Face Match and ID Verification use other endpoints (see Face Match / ID Verification in the sidebar).
Older Validations (HTTPS Links vs. kyc/... Keys)
- No data is deleted: existing API responses stay valid JSON; behavior depends on what each string contains.
- Keys (
kyc/...): useGET /api/kyc/validations/:id/mediawithkeyURL-encoded. Access is scoped to your organization and that validation. - HTTPS strings: your app should treat them like normal temporary asset URLs until they expire. The API may replace them with
kyc/...keys on a later sync with the verification provider (webhook or sync), as long as the hosted link can still be fetched. - If a link has already expired before migration, that field may stay as a dead URL until a new sync supplies fresh links or Gu1 support runs an internal media repair for your organization.
Request
Endpoint
GET https://api.gu1.ai/api/kyc/validations/{validationId}/media
Headers
Authorization:Bearer YOUR_API_KEY(required)
Query Parameters
| Parameter | Required | Description |
|---|---|---|
key | Yes | The storage key string from decision. URL-encode the value (slashes become %2F). |
Permissions
Your API key must be allowed to read KYC (kyc:read when the key uses granular permissions; otherwise the key follows the owner userβs role, with legacy fallback where applicableβsame as GET /api/kyc/validations/:id).
Response
Raw file bytes.Content-Type reflects the asset (e.g. image/jpeg, video/webm).
Example
curl -sS -o portrait.jpg \
-H "Authorization: Bearer YOUR_API_KEY" \
"https://api.gu1.ai/api/kyc/validations/VALIDATION_UUID/media?key=kyc%2Fglobal_gueno_validation_kyc%2F..."
encodeURIComponent(key) so every / in the key is encoded.
The
key query parameter alone is not a secret and does not replace authentication. Always send Authorization: Bearer; the API checks that the object key belongs to that validation and to your organization.Related
- Create KYC validation β start the flow and obtain
validationId - Check validation status β poll until
decisionis populated
Was this page helpful?